HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
MTG USA, Inc.
bd_126102988a477557 · schema v1 · pii pii-v1
Full breach record for MTG USA, Inc. →MTG USA, Inc. notified the New Hampshire Attorney General of a data breach affecting 3 state residents. Malicious code on the company website captured payment card information between June 25, 2020, and June 15, 2021. The company engaged a PCI Forensic Investigator, shut down the site, and migrated to Shopify. Affected individuals received 24 months of identity theft protection.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0018a6255b8b67f8California State AGfiled 2021-09-26(12d gap)Verified
- bd_3a8167a3ce491ba0Maine State AGfiled 2021-09-22(16d gap)Verified
- bd_323a0014aad80b9cMontana State AGfiled 2021-09-21(17d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mtg-usa-20211008.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 8, 2021
- Raw hash
- 3aebbff3aeb4fe2b00d74198cb926b9a06bb45741c055a50f0eff5b16f829ebf
Reporting entity
- Name
- MTG USA, Inc.norm: mtg usa
- Domain
- mtg-usa.com
Victim entity
- Name
- MTG USA, Inc.norm: mtg usa
- Domain
- mtg-usa.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Sep 16, 2021
- Affected individuals
- 3
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John M. Formella
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.